Security & How Your Funds Are Protected
Understanding Bundie security architecture and protection mechanisms
Security & How Your Funds Are Protected
Bundie is designed with security and transparency first. This guide explains how your funds are protected and what security measures are in place.
Non-Custodial Architecture
You Always Control Your Assets
What this means:
- Only you can deposit, withdraw, or allocate funds
- Your private keys never leave your wallet
- Bundie smart contracts are proxies, not custodians
- No admin backdoors to access user Accounts
How it works:
Traditional Finance:
You → Bank (holds your money) → Investments
Risk: Bank can freeze, lose, or misuse your funds
Bundie:
You → Your Account (you control) → Yield Strategies
Risk: Only smart contract risk, no custodial riskYour permissions:
- Deposit assets to your Account
- Allocate funds to strategies
- Withdraw from positions
- Withdraw from your Account to wallet
- Recover stuck ETH
Bundie CANNOT:
- Withdraw your funds
- Move your assets without approval
- Freeze your Account
- Block your withdrawals
- Access your private keys
Smart Contract Security
Audited Contracts
Bundie's core smart contracts were audited by Sherlock (April 2026), with critical findings fixed before mainnet launch and re-audits run on significant changes. The full report, including severity ratings and remediation status, is public: Bundie Collaborative Audit Report — Sherlock (April 2026).
Deployed Contracts
The full contract stack is deployed on each supported chain: Arbitrum (hub), Base, Optimism, Avalanche, and Scroll (legacy). Select a chain to see its verified addresses.
| Contract | Role | Address |
|---|---|---|
| AccountManager | Factory & beacon owner for user Accounts | 0x0e9aA7015773785c1A9dB9d2a8756c952BE096Cf |
| RouterManager | Factory for protocol routers | 0x92BF97347ea2037eC8E4b3762B7cCEB8017C255D |
| BridgeManager | Cross-chain bridge modules | 0x51B7112651867C7D6BC3d9e928F1b0E1839AE936 |
| VaultManager | Yield vault adapters (ERC-4626 / ERC-7540) | 0x101AC7546E60401e52450E4AF291a7396d137996 |
| LayerZero Bridge | LayerZero V2 bridge used by BridgeManager | 0x6b42ABb9b73A51e95B04e3F5C1fA1fE04293A802 |
| ERC-4626 Vault Module | Sync vault adapter | 0x272a25aB9Ee031eEbE69E2b90A6490eB9B636D0d |
| ERC-7540 Vault Module | Async vault adapter | 0xe33F804686bB04c70fAC94AfAcfF35438Eaab11c |
| Relayer | Fronts native ETH for bridge messaging fees | 0xC42969B0F0414f6183839F4f6F31B5fD02DaD4e8 |
| FeeManager | Fee configuration and collection | 0xC2226AF5FCa8A5dD5d92CBE1bD93E1B9441e27DC |
| Contract | Role | Address |
|---|---|---|
| AccountManager | Factory & beacon owner for user Accounts | 0x69c01ED80d5949E222d5638BA44373D3DCF0A4e7 |
| RouterManager | Factory for protocol routers | 0x7b8af9525F0183909eA985798D415422d875D93d |
| BridgeManager | Cross-chain bridge modules | 0x55c30aec0b8274347C76265373dcDeb04711BCd2 |
| VaultManager | Yield vault adapters (ERC-4626 / ERC-7540) | 0x40D67F50C5f1EfE784F4B21a09E23eCDf11b1Bd9 |
| LayerZero Bridge | LayerZero V2 bridge used by BridgeManager | 0xF0d20cB080786B3f42C5b6FB2a9D542F82336aA8 |
| ERC-4626 Vault Module | Sync vault adapter | 0x225457e01544b7516cfcd495c0862371a165F6A8 |
| ERC-7540 Vault Module | Async vault adapter | 0xF2255d2ebd8350DC62B4178dd9904eCE0f8f74d1 |
| Relayer | Fronts native ETH for bridge messaging fees | 0x26E550DBFa31362559d5f392d4DCe31Ef321aE87 |
| FeeManager | Fee configuration and collection | 0xD44681613A09B3EA2592D12b94207D6e45361D7d |
| Contract | Role | Address |
|---|---|---|
| AccountManager | Factory & beacon owner for user Accounts | 0x95CECcd40D98de57F0d93E659e1c966b11A1fb06 |
| RouterManager | Factory for protocol routers | 0x38Ba8BA3002A1D1984De2ec511D3C9Ffb3F4Ce26 |
| BridgeManager | Cross-chain bridge modules | 0xB4b991FE4aA691a366A08936dA582bE38eDfA690 |
| VaultManager | Yield vault adapters (ERC-4626 / ERC-7540) | 0xD158c69828b4BA5Ad9FCf5c04d67cf7641e4f938 |
| LayerZero Bridge | LayerZero V2 bridge used by BridgeManager | 0x7206bAcACF8F5f5162636f98CD106cdBD60e1d4E |
| ERC-4626 Vault Module | Sync vault adapter | 0x655d866C9d0546fFe616A30bbA32CDa6fe06d138 |
| ERC-7540 Vault Module | Async vault adapter | 0x2A40b9b06D58bBFD7dfe36cD9e7B4612Cd82a352 |
| Relayer | Fronts native ETH for bridge messaging fees | 0x9964411e45D8A47d6907dc2DAA0a78644AF3C7aa |
| FeeManager | Fee configuration and collection | 0xa5E9F24444Ce332a9302b8024036f5159199E50A |
| Contract | Role | Address |
|---|---|---|
| AccountManager | Factory & beacon owner for user Accounts | 0x9673FcfeDbb6C83c4a76f81Bcadf0fc8535EA9C5 |
| RouterManager | Factory for protocol routers | 0x4793281C20966e39DF90DE21624FF7C3Bb88dDb3 |
| BridgeManager | Cross-chain bridge modules | 0xF203f6261D58EA2d3294a552657890F76f37c9b5 |
| VaultManager | Yield vault adapters (ERC-4626 / ERC-7540) | 0x59e6B4d5B5438d68EBcc25431A041eed660357C7 |
| LayerZero Bridge | LayerZero V2 bridge used by BridgeManager | 0xc7cCA82eE2D7f530A4dc0e6844bfAC7b854F9551 |
| ERC-4626 Vault Module | Sync vault adapter | 0x541ad2f001106B38668Aee6E7E4BE8164b23A23a |
| ERC-7540 Vault Module | Async vault adapter | 0x210e466094B3812285796e17Bb7355375aF212D4 |
| Relayer | Fronts native ETH for bridge messaging fees | 0xA9Ffe99202BF2903E9405fDb304f4cEd7207473E |
| FeeManager | Fee configuration and collection | 0x42B93Cc00375479b8EA97041F7b4194fB98DC542 |
Scroll is supported as a legacy chain. New deposits target current chains; these contracts remain for existing positions.
| Contract | Role | Address |
|---|---|---|
| AccountManager | Factory & beacon owner for user Accounts | 0x2E70d2778d143412D66Edf835Be82DB29CB1ECfB |
| RouterManager | Factory for protocol routers | 0xFc309ed1FaCd18E942E3a245964D4F94fB4953F9 |
| BridgeManager | Cross-chain bridge modules | 0x2394C009feFf2CC18969FCcB43D49329a2D117fB |
| VaultManager | Yield vault adapters (ERC-4626 / ERC-7540) | 0x3F669f0368F6F00195B78fdcA0dC8Ea4636568B3 |
| LayerZero Bridge | LayerZero V2 bridge used by BridgeManager | 0xadf8cef9478E1E7B5d8E0e82aF63800693c22176 |
| ERC-4626 Vault Module | Sync vault adapter | 0x27D10d4E27595C6096F54F231a735e555Af0dD99 |
| ERC-7540 Vault Module | Async vault adapter | 0x6Ed8C9Cd2a2FD7265931E91C73570DAf6f7fF394 |
| Relayer | Fronts native ETH for bridge messaging fees | 0x0BE5034494A0210882e1641Ea6B482afAD01A47c |
| FeeManager | Fee configuration and collection | 0xF9f27e8B4d271827f8C9883aa184bAFFBda073f0 |
You hold one Account per chain — a personal smart contract deployed as a beacon proxy by AccountManager the first time you use that chain. You can look up your own Account address on the relevant block explorer after creation.
Beacon Proxy Pattern
Your Account is an upgradeable beacon proxy: all Accounts share one implementation, so security patches apply everywhere at once without you migrating funds, and your Account address never changes.
Upgrade safety:
- A 1-day timelock is enforced by the contract, so every upgrade is announced in advance
- Upgrades cannot access or move user funds, and all positions are preserved
- If you're not comfortable with a proposed upgrade, you can withdraw during the timelock
Reentrancy Guards — all deposit, withdrawal, allocation, and cross-chain operations are guarded against reentrancy and recursive-withdrawal attacks.
Whitelisted Tokens — only approved assets can be deposited, which blocks fake or malicious tokens. The current whitelist is USDC, USDT, ETH, and WETH; adding a new token requires a security review and governance approval.
Slippage Protection — every cross-chain deposit, withdrawal, and swap sets a minimum acceptable output. If the result would fall below it (unfavorable rates, fee spikes, low liquidity), the transaction reverts and your funds stay in your Account — you only pay gas.
Validator Trust Model
A validator monitors cross-chain operations and confirms them on-chain — it acts as a notary, not a custodian.
What it does: watches for bridge delivery, confirms completed deposits/withdrawals, and flags failed operations so funds can be refunded.
What it can't do: it holds no keys and has no spending permission, so it cannot move your funds, withdraw on your behalf, block your withdrawals, or fabricate a position you don't actually hold. The worst case is a delay in confirmation, never loss of funds.
Transparency: every validator action is recorded on-chain, so you can independently verify any confirmation against LayerZero Scan and the relevant block explorer.
Bridge Security
Cross-chain moves use LayerZero, an industry-standard messaging protocol used by 100+ protocols and audited by multiple firms. A transfer only updates your Account after the destination chain confirms receipt, and every step is publicly verifiable — the source and destination transaction hashes, the LayerZero message GUID, and the validator's confirmation are all on-chain (track via LayerZero Scan).
Failed Bridge Handling — if a bridge message fails to deliver, the destination protocol rejects the deposit, or an operation gets stuck, the validator flags it as failed on-chain and your funds are refunded to your Account. Manual recovery is available as a last resort, so funds are never permanently lost.
Emergency Recovery
Stuck ETH Recovery — if ETH ever ends up stuck in your Account (an accidental transfer, a refund), you can recover it to your wallet at any time from Account settings. It's a user-only action — no team approval required.
Failed Bridge Recovery
Failed bridges refund automatically (see Failed Bridge Handling above). If a refund doesn't go through, contact support with your operation's message GUID and the team will help you recover — funds are never lost, only delayed, and every recovery action is on-chain and verifiable.
Lost your message GUID? The transaction hash works for recovery too — or contact support with your Account address and the approximate time, and the team can locate the operation on-chain.
Protocol Risk Management
Strategy Vetting Process
Before a strategy is listed it must pass: an independent security audit with no critical findings, a maturity bar (≥ $10M TVL, 90+ days live, no major incidents), an ERC-4626-compatible interface (or a tested adapter), and reliable, manipulation-resistant price oracles. Listed strategies are then monitored continuously for TVL, APY anomalies, and incidents.
Risk Isolation
Position-level isolation:
- Each position is independent
- Exploit in one protocol doesn't affect others
- Your Account holds receipt tokens, not base assets directly
Example:
Your portfolio:
- 1,000 USDC in Aave (Arbitrum)
- 1,000 USDC in Morpho (Base)
- 1,000 USDC in Compound (Optimism)
If Aave is exploited:
Morpho position unaffected
Compound position unaffected
Aave position may lose value
Risk: Limited to 33% of portfolioDiversification — spreading across protocols and chains means no single point of failure, and bundles diversify automatically.
Incident Response
If an external protocol suffers a security incident, the affected strategy is disabled to new deposits and impacted users are notified (dashboard, email, and our channels) with recommended actions. You can exit the affected strategy at any time — move funds to another strategy or withdraw to your wallet — and we post updates as the situation develops.
Red Flags to Watch For
- 🚩 Sudden large APY increases (may indicate exploit)
- 🚩 Withdrawal delays (check protocol status)
- 🚩 Unusual Account balance changes (verify transactions)
- 🚩 Unannounced contract upgrades (should never happen)
If you see any of these: stop new deposits, check official channels, verify on-chain, and contact support.
Next Steps
- Risk & Security Overview - High-level security summary
- Bundie Collaborative Audit Report — Sherlock (April 2026) - Full audit report and findings
- Troubleshooting Guide - What to do if something goes wrong
- Key Concepts - Understanding the technical architecture
Ready to start securely? Launch Bundie App →